The images in this article were generated with artificial intelligence. How we publish
Roundcube Webmail, the web-based mail client who has been with millions of servers for years and who since 2008 has been integrated as a default interface in cPanel, was again placed at the centre of attention for reasons that any system manager should take seriously. The United States Infrastructure and Cybersecurity Agency (CISA) recently added two Roundcube failures to its catalogue of nature-exploited vulnerabilities and gave strict instructions for federal agencies to apply patches urgently.
The first noted failure allows remote code execution and is recorded as CVE-2025-49113. It was patched by Roundcube's officials, but researchers and monitoring organizations detected exploitation shortly after the correction was published, which motivated public alerts on tens of thousands of exposed facilities. The second problem, CVE-2025-68461, is a vulnerability of cross-site scribing (XSS) that abuses the animate label in SVG documents and that also has patch available from the versions that Roundcube published to correct it.

To contextualize the magnitude of the risk: search engines oriented to Internet-connected devices such as Shodan show tens of thousands of Roundcube instances accessible from the public network - a figure that indicates the enormous potential scope of any critical vulnerability in this software. See the public search for Shodan related to Roundcube Here..
CISA formalized the concern in an official alert in which it included both failures in its public communication and added the entries to the A catalogue of known and exploited vulnerabilities (KEV), a list the agency uses to prioritize defensive actions in the public sector. In addition, CISA recalled that there are other historical vulnerabilities in Roundcube that have been exploited by malicious actors, and that is why it included this family of failures in its continuous follow-up.
The federal government's response was rapid in terms of demand: through the binding operational directive known as BOD 22-01 Federal civil agencies were ordered to complete the necessary mitigation within three weeks. That hurry is not casual: vulnerabilities in web mail interfaces are attractive to criminals and state-sponsored groups because they offer relatively direct access to conversations and credentials, and because many facilities remain exposed for long periods.
Roundcube officials published corrections that organizations must adopt as soon as possible; the corrective versions for the supported branches are available on the official project channels and in the launch repositories. If you manage Roundcube servers, it is essential to update to the versions that include patches, review records for possible unauthorized access and minimize public exposure of the interface where possible. The project launch repository in GitHub is available for access to publications and official versions: Roundcube - Releases.
This is not the first time Roundcube has served as a vector for sophisticated campaigns. Historically, actors with political or criminal motivations have exploited failures of this software to spy on administrations and organizations. This pattern - public failure, patch and operation in a few days - highlights a simple but painful reality: the window between the publication of a patch and its effective deployment remains the main weakness in the safety of many infrastructure.

From a practical point of view, updating as soon as possible is the essential measure. In addition, it is appropriate to tighten the exposure of web mail interfaces through access rules, strong authentication, log monitoring and commitment indicators analysis. It is also recommended that security officials consult official intelligence sources and catalogues, such as the CISA list mentioned above, to prioritize actions based on the real risk and presence of the software in their environment.
The lesson that this episode leaves is clear: even widely deployed and long-standing tools can become a systemic risk if the updates are not applied quickly and if the telemetry on their exposure is not integrated into the security processes. Keeping the software up to date, reducing the exposed surface and actively monitoring environments are practical that together make the difference between a protected patch and a patch that comes too late.
Recommended sources and readings: the entry of CISA on the inclusion of these vulnerabilities in its catalogue Here., technical details at the National Vulnerability Database for CVE-2025-49113 and CVE-2025-68461, the public search for Roundcube's Shodan and the official Roundcube launch repository in GitHub.
Related
More news on the same subject.

Florida, Iowa, Montana and Nebraska sue TP-Link Systems for security and source of routers
On October 6, four State Attorney General filed complaints against TP- Link Systems in U.S. state courts - in addition to a previous Texas lawsuit - for business practices relat...

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...